Strongwork welcomes good-faith reports that help protect our products, customers, and users.
Email info@strongwork.com with the subject Security vulnerability report. If your report contains sensitive information, first ask us to arrange an approved secure transfer method.
Use only the minimum access needed to confirm an issue. Stop testing and report promptly if you encounter customer data, credentials, confidential information, or evidence of active compromise. Do not retain or disclose that information.
Unless Strongwork gives specific written authorization, do not perform denial-of-service or destructive testing, social engineering, credential attacks, testing of another person's account, data exfiltration, physical testing, or testing of third-party systems that Strongwork does not own or control.
We will make reasonable efforts to acknowledge a usable report, validate it, and coordinate appropriate remediation and disclosure. Timing depends on severity, complexity, affected parties, and operational risk. This reporting channel does not create a bug bounty, guaranteed response time, reward, contract, or entitlement to public disclosure.